Loan Origination11 min read

Loan Origination System RFP Checklist for Kenyan Banks and SACCOs (Free Scoring Template)

A 50-point loan origination system RFP checklist for Kenyan banks, SACCOs and MFIs: vendor questions, evidence requests and a free Excel scoring template.

CS
Creodata Solutions Team
September 23, 2026
Loan Origination System RFP Checklist for Kenyan Banks and SACCOs (Free Scoring Template)

Short answer: Score loan origination system vendors on evidence from your own products, not on their standard demo. Our free checklist gives you 50 requirements in nine areas, the question to put to each vendor, the evidence to ask for, and a spreadsheet that weights and scores up to three shortlisted suppliers.

Download the loan origination system RFP checklist and scoring template (Excel, 25 KB)

Every loan origination software brochure promises configurable workflows and fast approvals. The differences show up only when you ask specific questions: can an administrator add a stage without the vendor's developers, which IPRS, CRB and core-banking integrations are live in Kenya today, and can the system prove who approved a loan last year, within which limit? A scored process also gives your board, auditors and regulator a record of why you chose the vendor you did.

A word on who wrote this. Creodata sells loan origination software for Kenyan banks, SACCOs and MFIs, so we have written criteria that any serious vendor, including us, should be able to evidence. Use it to score us alongside everyone else. This is a procurement aid, not legal advice: confirm current requirements against the law and your regulator's guidance before you issue an RFP.

What is in the checklist

The workbook has three tabs. Read me explains how to use it and the scoring scale. Requirements holds the 50 requirements, each with why it matters in Kenya, the question to ask, the evidence to request, a priority, an optional weight override and scores for up to three vendors. Scoring summary calculates the results.

AreaRequirementsWhat it tests
1. Workflow and approval matrix5Configurable stages, routing by amount and risk grade, maker-checker, coded reasons, committee decisions and conditions
2. Application intake and documents6Product-specific checklists, document versioning, guarantors, group and bulk applications, channels, duplicates
3. Credit assessment5Credit proposal, affordability rules, collateral, risk grading and policy exceptions, pre-disbursement gate
4. Kenyan integrations8IPRS, CRBs, KRA PIN, sanctions and PEP screening, core banking, check-off and IPPD, SACCO systems, disbursement
5. SLA and turnaround visibility4Stage SLAs, escalation, live pipeline, status notifications
6. Audit trail, access control and security5Append-only audit log, role-based access, single sign-on and MFA, segregation of duties, security testing
7. Data protection and hosting6Data Protection Act, 2019 support, processing agreement, data location, on-premises option, cross-border transfers, recovery
8. Reporting and regulatory data4Standard reports, BI access, data for CBK or SASRA returns, insider and related-party loans
9. Vendor, delivery and commercials7Kenyan references, local support, implementation plan, licensing, three-year cost, exit, escrow

Of the 50 requirements, 28 are marked Must, 20 Should and 2 Could. By default a Must weighs 5, a Should 3 and a Could 1; you can change those defaults on the summary sheet, or type a number in the Weight override column to set the weight of any single requirement. Vendors are scored from 0 (not available) to 5 (exceeds the requirement, with evidence from production), with 3 meaning "meets it with configuration". The summary shows each vendor's weighted score, coverage, a must-have failures count of Must items scored below 3, and a score by area, so strength in one area cannot hide weakness in another.

How to run the process

  1. Define scope. Agree the products in scope, where origination ends and your core banking or SACCO system takes over, and the integrations you need. Credit, risk, IT, compliance and procurement set the priorities before anyone meets a vendor.
  2. Long-list by provider type. Global LOS suites, core-banking add-ons, local loan management and SACCO systems, digital-lending platforms and workflow-first LOS products solve different problems; our buyer's guide to loan origination software in Kenya maps each. A short request for information built from your Musts removes vendors that cannot meet the basics.
  3. Issue the RFP. Send the "Ask the vendor" and "Evidence to request" columns and require written answers, including whether each integration is live in Kenya, planned or to be built.
  4. Run scripted demos on your own products, approval matrix and sample applications (see below).
  5. Call references of similar size and type, and ask what went wrong, not only what went right.
  6. Score independently, then calibrate as a panel, which limits anchoring on the loudest voice.
  7. Negotiate. Compare three-year costs on the same basis, read the exit clause, and agree what counts as configuration versus a paid change request.
  8. Write the board paper. Attach the workbook, area scores, must-have failures and reference notes, so your board, auditors and examiner can see how the choice was made.

The nine areas, and the questions that decide most evaluations

1. Workflow and approval matrix

This is the heart of a loan origination system, so test it live. Ask the vendor to add a stage to one product's workflow and show the change was versioned and approved. Route three applications of rising amounts to branch committee, management committee and Board, and ask whether a limit change is maker-checked. Try to have one user capture and approve the same file. Returns and declines need coded reasons, and committee decisions should record members, comments and conditions, with disbursement blocked while a condition is open. Our guide to credit approval workflows in Kenyan banks covers committee routing in depth.

2. Application intake and documents

Configure a checklist for a new product, then try to move an application forward with a mandatory document missing. Ask to see a replaced document, its earlier version and who verified it. For SACCOs and MFIs, ask to see one guarantor's total exposure across all loans, and how group loans and employer-scheme batches are handled. Submit a duplicate application and see what the system matches on: ID number, phone number or KRA PIN.

3. Credit assessment

Ask the system to generate a credit proposal from captured data on a template you can edit. Affordability rules should be configurable per product: net pay for check-off, cash flow for SME. Ask how collateral valuations, charge registration and insurance expiry are recorded, how policy exceptions are routed for higher approval, and exactly what the pre-disbursement gate checks and who can override it.

4. Kenyan integrations

This area has the most rows because most implementations slip here. The workbook treats integration rows as questions, not claims:

  • IPRS: direct or through an intermediary, which institutions use it in production, and what happens when IPRS is unavailable.
  • CRBs: which licensed credit reference bureaus are integrated today, whether the report is stored with the application, and how another bureau would be added.
  • KRA PIN, sanctions and PEP screening: whether screening is native or calls your existing AML system, and how hits stop the application.
  • Core banking: which core systems the vendor has integrated with in Kenya, whether booking and disbursement are automatic, and how failed postings are reconciled. See LOS integration with core banking.
  • Check-off and IPPD: how payroll deduction capacity is confirmed and check-off schedules produced. The Employment Act caps total deductions at two-thirds of wages, so capacity must be known before approval. See check-off loans in Kenya.
  • SACCO systems: how member deposits, shares, existing loans and guarantor commitments are read from BOSA and FOSA.
  • Disbursement: which channels are supported, and how payment status returns to the application.

See compliance checks in loan origination in Kenya for how these results reach every reviewer.

5. SLA and turnaround visibility

Applications sitting unnoticed in a queue are the commonest cause of slow turnaround. Ask for stage SLAs per product, what happens on breach and who is escalated to, and whether the clock pauses while you wait for the customer. Then drill from a branch in the live pipeline to one delayed application. Loan processing turnaround time and SLAs explains how to make origination measurable.

6. Audit trail, access control and security

Ask whether any user, including an administrator, can edit or delete an audit entry, and see the full log for one application. Access should be scoped by role, branch, product and limit, conflicting roles blocked, and approvers on single sign-on with multi-factor authentication. Ask when the last independent penetration test took place and how findings were closed. The audit trail, RBAC and security guide sets out what good looks like.

7. Data protection and hosting

Ask how the system supports consent, data-subject requests, retention and deletion under the Data Protection Act, 2019, and whether the vendor will sign a data processing agreement. Registration with the Office of the Data Protection Commissioner is your own duty; financial-services controllers register regardless of turnover. Ask where production data, backups and disaster-recovery copies sit, whether any data leaves Kenya, whether the same product runs on-premises and in the cloud, and when disaster recovery was last tested.

8. Reporting and regulatory data

Export a standard report during the demo, and ask whether your analysts can connect a BI tool without a change request. Returns are usually produced from the core system, so ask which origination fields pass to core and whether they map to your CBK or SASRA return classifications. Insider and related-party applications should be flagged and routed at origination.

9. Vendor, delivery and commercials

Ask for two comparable Kenyan references, support in East Africa Time, and a plan with a named team that explains how in-flight applications migrate at cut-over. Ask for a transparent licence model and a three-year cost that includes every integration in area 4. Read the exit clause: loan files, documents and audit history must come back in open formats.

How to weight the requirements

Agree weights before you see any vendor, so scoring reflects your risks rather than the best demo. Start with the defaults, then adjust:

  • A bank or microfinance bank may raise insider and related-party lending (R8.4) to Must.
  • A SACCO will usually raise SACCO system integration (R4.7) to Must and may lower collateral or group lending if they do not apply.
  • A payroll lender should raise check-off and IPPD (R4.6) to Must.
  • An MFI with field officers may raise multi-channel and offline capture (R2.5) and group lending (R2.4).

Change priorities rather than deleting rows, so the record shows what you considered. Then read must-have failures alongside the total: a high score with two Musts below 3 still has a gap no strength makes up for.

Five scripted demo scenarios to give every vendor

Send the script and your sample data a week ahead, and give every vendor the same time.

ScenarioWhat to watch
Configure one of your real products, with its document checklist and approval routeWho does it, whether code is needed, and whether the change is versioned and approved
Route three applications of rising amounts, then change the amount of one after committeeCorrect routing to branch committee, management committee and Board, and re-routing when the amount changes
Take a check-off or SACCO application through IPRS, CRB and screening, with one service unavailableResults stored with the file, what the user sees on failure, and how the check is retried
Approve a loan with an open condition precedent and try to disburseWhether the pre-disbursement gate blocks it, and who can override
Ask for the evidence on an application approved last monthHow quickly the full history, document versions, approvers and limits appear

Red flags

  • The vendor will only demonstrate its own sample products.
  • Adding a workflow stage or changing an approval limit needs the vendor's developers.
  • Integrations are described as "available" but no Kenyan institution uses them in production.
  • An administrator can edit or delete audit entries.
  • The answer to "where is our data?" changes between the sales call and the contract.
  • Must-have requirements are answered with roadmap dates.
  • The three-year cost leaves out integrations, change requests or hosting.
  • No reference institution of similar size and type will take a call.

Where Creodata fits

Score us alongside everyone else. Creodata's loan origination system is a workflow-first LOS, and its strongest rows are in areas 1, 5 and 6: a 13-stage, role-gated workflow from application intake to final disbursement; amount-based routing through the business credit committee, Head of Corporate or Retail, management credit committee, Committee or Board, and risk gates, with the amount re-checked at every decision; an SLA timer on every stage with escalation of breached applications; an audit trail of every decision, assignment and document action; and Azure AD/Entra ID or LDAP sign-in with role-based access. Products and routing rules are configured without code, and it runs on Microsoft Azure or on-premises with the same features.

For check-off lending, our Workplace Banking Application covers much of area 4: IPRS, CRB, KRA and sanctions/PEP checks, IPPD deduction data and Finacle core banking integration. We do not service loans or disburse to mobile money; those rows belong to your core system or another platform. Pricing is quoted per institution. Ask us for the same evidence as everyone else, and book a demo with your own scenarios.

Frequently asked questions

What should a loan origination system RFP include?

Your scope and priorities, the requirements with the question each vendor must answer, the evidence you expect, the demo scenarios, and the information needed for a three-year cost comparison. Also ask about integrations live in Kenya, data location, implementation responsibilities and exit terms, which are most often left vague until contract negotiation.

How should we weight requirements when comparing LOS vendors?

Agree weights before you meet any vendor. The defaults weigh a Must 5, a Should 3 and a Could 1, and any requirement can be overridden. Read the must-have failures count as well as the total.

Should a SACCO use the same checklist as a bank?

Yes, with different priorities: more weight on guarantor exposure, SACCO system integration and cost. Change priorities rather than deleting rows. Our guide to SACCO loan origination software in Kenya covers SACCO-specific needs.

How many LOS vendors should we shortlist?

Long-list five to eight suppliers across provider types, then take two or three to scripted demos and reference calls. The summary is built for three vendors.

Does the checklist cover CBK digital lending rules?

It covers controls most lenders need, such as data protection, audit trail and approval evidence, but not every rule in the CBK (Digital Credit Providers) Regulations, 2022 or the 2025 draft regulations for non-deposit-taking credit providers. Add rows for your own obligations; our article on CBK digital lending compliance is a starting point.

Is the checklist free to use and edit?

Yes. Download it, edit the requirements and priorities, add your own rows and share it inside your institution. If you insert a requirement, insert it inside the table and copy the formulas in columns I and M to O so the summary includes it.


Download the loan origination system RFP checklist and scoring template, read the buyer's guide to loan origination software in Kenya, or see how Creodata's loan origination software scores against it in a demo.

See Loan Origination in action.